Courseiva

Automatic Deprovisioning of External Users in Microsoft Entra ID

Your company uses Microsoft Entra ID for identity management. You need to implement a solution that allows external partners to access a specific application using their own identity providers, while ensuring that their accounts are automatically deprovisioned when removed from their home organization. Which feature should you use?

Quick Answer

The answer is Entitlement management with connected organizations, as this is the only feature in Microsoft Entra ID that provides automatic deprovisioning of external users when they are removed from their home organization. This works because Entitlement management ties access packages to connected organizations, enabling lifecycle-based provisioning and deprovisioning—when the external user’s membership in their home tenant ends, Entitlement management automatically removes their access and account. On the Microsoft Cybersecurity Architect exam, this question tests your understanding of Identity Governance scenarios, often appearing as a trap where B2B direct federation or self-service sign-up seems plausible but lacks automated deprovisioning. A common memory tip is to remember that “connected organizations” are the key to automated lifecycle management for external users, while other B2B features only handle initial access. Think of it as “connected for lifecycle, not just for login.”

⚠ Common exam trap

SC-100 often tests the confusion between B2B direct federation (authentication trust only) and entitlement management with connected organizations (full governance plus automatic deprovisioning), causing candidates to pick the simpler federation option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entitlement management with connected organizations

Entitlement management with connected organizations in Microsoft Entra ID (part of Identity Governance) is designed exactly for this scenario: it lets you onboard external partners, define access packages tied to their home identity providers, and automatically deprovision access when the user leaves their home organization via lifecycle workflows and connected-organization sync. This provides both the cross-tenant access and the automatic deprovisioning requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    B2B direct federation

    Why it's wrong here

    B2B direct federation lets partners authenticate with their own SAML/WS-Fed IdP, but it does not provision or deprovision guest accounts in Microsoft Entra ID. It suits one-off partner access where lifecycle management is handled manually, not the automatic removal required when a user leaves their home organisation.

  • ✓

    Entitlement management with connected organizations

    Why this is correct

    Entitlement management with connected organizations lets external partners authenticate via their own identity providers while Microsoft Entra ID governs access through access packages. Lifecycle workflows automatically deprovision those accounts when partners leave their home organization, meeting the automatic removal requirement.

  • ✗

    Self-service sign-up

    Why it's wrong here

    Self-service sign-up lets external users request access via a custom application, but it creates no lifecycle link to their home organisation, so removal there does not deprovision the guest account. It fits open enrolment scenarios such as consumer apps, not managed partner access with automatic deprovisioning.

  • ✗

    Identity Governance access reviews

    Why it's wrong here

    Access reviews periodically recertify existing guest access but do not automatically deprovision accounts when a partner leaves their home organisation; they rely on reviewers acting. Access reviews suit attestation and compliance for standing access, not the entitlement lifecycle synchronisation that cross-tenant provisioning provides.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses Microsoft Entra ID for identity management. They want to ensure that only approved users can access a custom web application. The solution must support single sign-on (SSO) and require multi-factor authentication (MFA) for external users. Which approach should they use?

easy
  • A.Register the application in Microsoft Entra ID and configure SAML-based sign-on
  • B.Use Azure AD Application Proxy to publish the app
  • ✓ C.Configure Microsoft Entra B2B collaboration and set MFA trust settings
  • D.Register the application in Microsoft Entra ID and assign app roles

Why C: Option C is correct because Microsoft Entra B2B collaboration is designed to onboard external (guest) users into the tenant, and its MFA trust settings let you enforce multi-factor authentication for those guests while they use SSO to access the custom web application. This directly satisfies the requirement that only approved external users get access with SSO and MFA. Option A enables SAML SSO but does not by itself govern external user onboarding or MFA for guests. Option B (Azure AD Application Proxy) is for publishing on-premises apps to remote users, not for managing external user identity and MFA. Option D assigns app roles for authorization but does not provide the external-user collaboration or MFA enforcement required.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.